Skip to main content
Solved

Splunk / SIEM Integration

  • September 13, 2023
  • 2 replies
  • 140 views

Kachow
Forum|alt.badge.img

I’d like to use FN APIs to integrate with Splunk and SIEM / Security systems. Has anyone else done this?

Best answer by GTurner

Hi Kristopher. We have many customers that have successfully integrated with Splunk.  At a very highlevel, an NQE query is developed to extract the desired data from the Forward Platform.  The data is extracted in a structured format and easily ingested into Splunk via a 3rd party Splunk app accessing the data through Splunk forwarders.  Before developing the 3rd party app, I suggest creating the query an ingesting through the Splunk Web interface to ensure the proper visualization, indexing, etc. is achieved.  

In this example, The customer wants to ensure that best practices for device hardening are followed.  We begin by ingesting the NQE output compliant with the best practices and from this point simple dashboards are created for simple at-a-glance consumption.

 

View original
Did this topic help you find an answer to your question?

2 replies

catbanks
Forum|alt.badge.img
  • Ramping Up
  • 1 reply
  • September 21, 2023

1


GTurner
Employee
  • Employee
  • 1 reply
  • Answer
  • October 6, 2023

Hi Kristopher. We have many customers that have successfully integrated with Splunk.  At a very highlevel, an NQE query is developed to extract the desired data from the Forward Platform.  The data is extracted in a structured format and easily ingested into Splunk via a 3rd party Splunk app accessing the data through Splunk forwarders.  Before developing the 3rd party app, I suggest creating the query an ingesting through the Splunk Web interface to ensure the proper visualization, indexing, etc. is achieved.  

In this example, The customer wants to ensure that best practices for device hardening are followed.  We begin by ingesting the NQE output compliant with the best practices and from this point simple dashboards are created for simple at-a-glance consumption.

 


Reply


Cookie policy

We use cookies to enhance and personalize your experience. If you accept you agree to our full cookie policy. Learn more about our cookies.

 
Cookie settings